National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.

Slides:



Advertisements
Similar presentations
National Institute of Advanced Industrial Science and Technology Asia Pacific Grid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Advertisements

2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Resource WG Report. Projects Applications EOL Ninf-G Climate model GridBlast GOC Gangla / SCMSWeb => Uniform Database Goodness Status map (e.g. IVDGL)
Introduction of Grid Security
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
National Institute of Advanced Industrial Science and Technology Proposals for auditing Yoshio Tanaka Grid Technology Research.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
National Institute of Advanced Industrial Science and Technology Status and plans of the APGrid PMA Yoshio Tanaka Grid Technology.
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 Wireless LAN SSID: PRAGMA11 Wep key: PRAGMA11JAPAN.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
National Institute of Advanced Industrial Science and Technology ApGrid: Current Status and Future Direction Yoshio Tanaka (AIST)
AustrianGrid, LCG & more Reinhard Bischof HPC-Seminar April 8 th 2005.
National Institute of Advanced Industrial Science and Technology Introduction to Grid Activities in the Asia Pacific Region jointly presented by Yoshio.
National Computational Science National Center for Supercomputing Applications National Computational Science Alliance Setup Package Requirements Jim Basney.
Grid security in NAREGI project NAREGI the Japanese national science grid project is doing research and development of grid middleware to create e- Science.
Grid security in NAREGI project July 19, 2006 National Institute of Informatics, Japan Shinichi Mineo APAN Grid-Middleware Workshop 2006.
1 TAPAS Workshop Nicola Mezzetti - TAPAS Workshop Bologna Achieving Security and Privacy on the Grid Nicola Mezzetti.
Digital Object Architecture
PRAGMA: Cyberinfrastructure, Applications, People Yoshio Tanaka (AIST, Japan) Peter Arzberger (UCSD, USA)
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
National Institute of Advanced Industrial Science and Technology Introduction of PRAGMA routine-basis experiments Yoshio Tanaka
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka Grid Technology Research.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
The Grid System Design Liu Xiangrui Beijing Institute of Technology.
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
ESnet PKI Developed for the DOE Science Grid and SciDAC.
Grid Middleware Tutorial / Grid Technologies IntroSlide 1 /14 Grid Technologies Intro Ivan Degtyarenko ivan.degtyarenko dog csc dot fi CSC – The Finnish.
National Computational Science National Center for Supercomputing Applications National Computational Science Credential Management in the Grid Security.
Authors: Ronnie Julio Cole David
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Oxford University e-Science Centre 1 Managing Access 4 Dec Managing Access to Resources on the Grid 4 December 2002.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
Manish Mehta, CS 590L Authentication Services in Open Grid Services by Manish Mehta April 27, 2004.
National Institute of Advanced Industrial Science and Technology APGrid PMA: Stauts Yoshio Tanaka Grid Technology Research Center,
Ruth Pordes November 2004TeraGrid GIG Site Review1 TeraGrid and Open Science Grid Ruth Pordes, Fermilab representing the Open Science.
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Introduction to Grids By: Fetahi Z. Wuhib [CSD2004-Team19]
National Institute of Advanced Industrial Science and Technology ApGrid: Asia Pacific Partnership for Grid Computing - Introduction of testbed development.
Authorisation, Authentication and Security Guy Warner NeSC Training Team Induction to Grid Computing and the EGEE Project, Vilnius,
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Open Science Grid & its Security Technical Group ESCC22 Jul 2004 Bob Cowles
1 Grid Activity Summary » Grid Testbed » CFD Application » Virtualization » Information Grid » Grid CA.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America gLite Information System Claudio Cherubino.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
April 4, 2002Atlas Testbed Workshop ATLAS Hierarchical MDS Server Patrick McGuigan.
MGRID Architecture Andy Adamson Center for Information Technology Integration University of Michigan, USA.
APGridPMA Update Eric Yen APGridPMA August, 2014.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
Organized by governmental sector (National Institute of information )
OGSA-WG Interim F2F Meeting Security Feb. 9-10,2004
OGSA-WG Security Use Cases Jan 29, 2004
Presentation transcript:

National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access control panel Experiences in Asia Pacific Yoshio Tanaka Grid Technology Research Center, AIST, Japan

Architecture, technology Architecture, technology Based on GT2 Based on GT2 Allow multiple CAs Allow multiple CAs Build MDS Tree Build MDS Tree Grid middleware/tools from Asia Pacific Grid middleware/tools from Asia Pacific Ninf-G (GridRPC programming) Ninf-G (GridRPC programming) Nimrod-G (parametric modeling system Nimrod-G (parametric modeling system) SCMSWeb (resource monitoring) Grid Data Farm (Grid File System), etc. Status Status 22 organizations (10 countries) 23 clusters (1688 CPUs) Grids in Asia Pacific

Grass-roots Approach (strategy) Assumption Each institution has installed GT2 Necessary steps Gather and exchange trusted CA info. and trust with each other Configure MDS to build an ApGrid MDS tree For application use Install additional software in project-basis CA globus CA CA CA CA CA CA CA CA ApGrid GIIS

Status and problems Most participating organizations have less interests in Security Many participants are application people Not enough human resources working on security Satisfy in using Globus Simple CA without providing CP/CPS This would be acceptable inside AP for experimental use. potential/ongoing collaboration with US and EU e.g.: AIST/Japan – TeraGrid KISTI/Korea – PPDG and iVDGL ASCC/Taiwan – LCG … Need to launch production level CAs

APGrid PMA: Asia Pacific Grid PMA General Policy Management Authority in Asia Pacific Launched on June 1 st, 2004 Defines minimum CA requirements APGrid PMA approved that we accept two levels of CA: Experimental-level CA Alternative of the Globus CA Can be trusted within A-P communities Production-level CA Strict management is necessary Expected to be trusted by international communities KISTI GRID CA has been approved as a production level CA AIST GRID CA and ASGC CA are under reviewing their CP/CPS (expected to be approved shortly) Will discuss on interoperability issues between AP, EU and the US

Virtual Organization user 1 ( VO Manager ) service_c service_a Services and Users are exposed in a Virtual Organization Organization A service_c service_b service_a user 2 user 3 user 1 Contract A service_x service_y user p service_z service_x service_y user p user q user r Organization B Contract B PKI Domain VO Domain Identification and Authentication of VO membership Work in Japanese NAREGI (National Research Grid Initiative) Project ISSUES : How to identify and authenticate members inside VO Design PKI architecture, trust relationship between end entity and CA Implementation issue of Globus and Unicore A virtual organization(VO) is a dynamic collection of resources and users unified by a common goal and potentially spanning multiple administrative domains. slide by courtesy of Ayako Komatsu (NEC)

ID & AUTH of VO membership (cont ’ d) Launch VO-CA that issues Public Key Certificates for end entities EE has both home PKC and a PKC issued by Compatible with Globus and Unicore Need to consider relationship between VO-CA and home CA Several implementation choices parent CA, child CA, bridged-CA, etc. Use attributes Manage membership information as an attribute of EE Authentication using a PKC issued by a home CA, then refer membership information Need to consider the scope of attributes slide by courtesy of Ayako Komatsu (NEC)

Identifier Access Rights Attribute Authenti cation Identity Federation Accoun ting Author ization Grid Computing NAREGI VO management architecture PKI GroupMgmt. Group VO Management Monit oring Human JobResource User Proxy UNICORE Globus Identifier slide by courtesy of Ayako Komatsu (NEC)

More Information ApGrid APGrid PMA My address